Skip to main content

07 - References & Standards

This chapter provides an exhaustive index of regulatory standards, official specifications, foundational academic literature, open-source tools, and historical CVE case studies relevant to architectural security design patterns.


📜 Industry Frameworks & Regulatory Standards

  • NIST SP 800-160 Vol. 1 Rev. 1: Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems. National Institute of Standards and Technology. NIST Publication SP 800-160
  • NIST SP 800-207: Zero Trust Architecture (ZTA). Defines core tenets of identity-centric security boundaries and micro-perimeters. NIST SP 800-207
  • OWASP ASVS v4.0.3: Application Security Verification Standard. Chapter 1 (Architecture, Design, and Threat Modeling). OWASP ASVS
  • OWASP SAMM v2.0: Software Assurance Maturity Model. Architectural Assessment and Design Review practice. OWASP SAMM
  • PCI-DSS v4.0: Payment Card Industry Data Security Standard. Requirement 3 (Protect Stored Account Data - Tokenization/Envelope Encryption) and Requirement 6 (Develop Secure Systems and Software). PCI Security Standards Council

🌐 Official RFC Specifications & Technical Standards

  • RFC 8693: OAuth 2.0 Token Exchange. Defines standard request/response structures for exchanging tokens across microservices. IETF RFC 8693
  • RFC 7519: JSON Web Token (JWT). Format specification for claims-based authorization tokens. IETF RFC 7519
  • SPIFFE Standard: Secure Production Identity Framework for Everyone. Defines SPIFFE IDs and X.509 SVID specifications. SPIFFE Standard

📚 Foundational Literature & Textbooks

  • Saltzer, J. H., & Schroeder, M. D. (1975). The Protection of Information in Computer Systems. Proceedings of the IEEE, 63(9), 1278-1308. (The seminal paper introducing security design principles).
  • Richardson, C. (2018). Microservices Patterns: With Examples in Java. Manning Publications. (Covers Circuit Breaker, API Gateway, and Sidecar patterns).
  • Adkins, H., Beyer, B., Blankinship, P., Lewandowski, M., Oprea, A., & Stender, J. (2020). Building Secure and Reliable Systems: Best Practices for Designing, Implementing, and Maintaining Systems. O'Reilly Media. Google SRE Books
  • Schumacher, M., Fernandez-Buglioni, E., Hybertson, D., Buschmann, F., & Sommerlad, P. (2006). Security Patterns: Integrating Security and Systems Engineering. John Wiley & Sons.

🛠️ Security Architecture Tools & Frameworks

  • Envoy Proxy: High-performance L7 proxy designed for service meshes. Envoy Proxy Documentation
  • SPIRE: SPIFFE Runtime Environment for workload attestation and certificate issuance. SPIRE GitHub
  • HashiCorp Vault: Secure secrets management and Transit Data Encryption engine. HashiCorp Vault
  • OWASP Threat Dragon: Open-source threat modeling diagramming tool. Threat Dragon
  • PyTM: Python-based framework for threat modeling as code. PyTM Repository

🚨 Real-World Incident Case Studies (Design Pattern Failures)

Incident / CVEVulnerability TypeDesign Pattern FailureImpact / Lessons Learned
CVE-2021-44228 (Log4Shell)Remote Code ExecutionComplete Mediation & Input SanitizationJNDI strings were evaluated recursively in log context without input sanitization pipelines.
Capital One Breach (2019)Server-Side Request ForgeryDefense in Depth & Token DownscopingCompromised WAF role had overly broad IAM permissions allowing direct access to S3 buckets.
CVE-2020-0601 (Windows CryptoAPI)Elliptic Curve SpoofingOpen Design & Cryptographic ValidationSystem failed to validate standard generator parameters for ECC root keys, enabling spoofing.
Knight Capital Outage (2012)System Failure CascadeCircuit Breaker & Fail-Safe DefaultsStale code on un-decommissioned server executed loops without circuit breaking, incurring $440M loss in 45 mins.

[!TIP] Congratulations! You have completed the Security Design Patterns guide. Return to the README.md overview or explore other AppSec Atlas modules.

Share this guide